ARKTunnel service persistence via wscl-13 or msvcsrvc
This rule detects the creation of Windows services with specific, potentially suspicious names (wscl-13, msvcsrvc) configured to start automatically on system startup. The detection logic monitors command-line activity from sc.exe or services.exe to identify these specific service registrations.
Microsoft Sentinel (KQL)

